Home / Health / Healthcare giant hid patient data breach for 15 months
Healthcare giant hid patient data breach for 15 months
15 Sep
Summary
- Patient data breach occurred in February 2025.
- Affected information includes names, addresses, and NHS numbers.
- Patients were only notified about the breach 15 months later.
A healthcare provider operating NHS-funded services has faced scrutiny over a significant delay in notifying patients about a cyber attack. The incident, which happened in February 2025, potentially exposed personal details such as names, addresses, dates of birth, and NHS numbers.
Patients began receiving letters regarding the breach approximately 15 months after the attack occurred. This delay has caused considerable concern among staff and the public, particularly due to allegations that the compromised systems may have contained highly sensitive safeguarding information.
The company stated that they acted swiftly to contain the incident, reported it to authorities, and have provided support to affected individuals. They emphasized that the breach was previously disclosed and there is no evidence of data misuse or online appearance. The Information Commissioner's Office concluded its consideration of the incident without further action.